Personal Vault showing old email address as primary verification method

William Passey 0 Reputation points
2026-05-13T22:52:42.5866667+00:00

"I have an issue with my OneDrive Personal Vault that Microsoft support has been unable to resolve for over a year.

When I attempt to access my Personal Vault, my old email address still appears as the primary verification method. This email address no longer exists and I no longer have access to it.

I have already done the following:

  • Checked my security settings at account.microsoft.com/security
  • The old email address is NOT listed under Manage how I sign in
  • Only my current Gmail address and mobile number are listed
  • Removed my wife's email which was also listed

Despite this, the old email still appears every time I try to access the Vault. I have to select Show more verification methods and use my mobile number each time.

I have a support case open (Case 7102560540) but after multiple emails I am still receiving generic troubleshooting steps that have not resolved the issue.

The old email appears to be hardcoded into the Personal Vault verification system and cannot be removed through standard account security settings.

Has anyone else experienced this and is there a fix?"

Microsoft Security | Microsoft Identity Manager
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-05-13T22:52:58.89+00:00

    The Personal Vault verification prompt uses the same Microsoft account security info that is managed from the account’s security settings. If an old email address still appears as a verification option even though it is no longer shown under “Manage how I sign in,” the only supported way to remove it is to manage security info from the Advanced security options page and remove outdated verification methods there.

    Follow these steps:

    1. Go to the Advanced security options page for the Microsoft account and sign in: use the Sign in link from the “Removing a sign-in verification method” article.
    2. In Advanced security options, locate all verification methods (email addresses, phone numbers, etc.).
    3. Expand each verification option and select Remove for any method that is no longer valid.
    4. Select Remove again to confirm.

    Important considerations from the documented behavior:

    • Old security information does not need to be removed unless there is an account security risk (for example, someone else has access to the old mailbox). However, in this scenario the old email is no longer accessible and is still being offered as a verification method, so it should be removed.
    • Before removing any existing security info, add a new method first (for example, a current email or phone) so there is always at least one valid verification method on the account.
    • Do not request removal of all security information at once. If all security info is removed, the account is placed into a restricted state for 30 days, during which no further security or billing changes can be made.

    If the old email address does not appear even in Advanced security options, but still shows in the Personal Vault prompt, this falls outside what can be changed through documented self-service steps. In that case, the only path is to continue working with Microsoft Support, referencing the existing case, and ask them specifically to review and correct any stale verification methods associated with the Personal Vault / OneDrive security configuration.

    For general OneDrive Personal Vault issues (such as sync or lock/unlock problems), the documented steps are to unlock the vault, ensure all files are closed, wait for sync to complete, and then lock it again. However, these steps do not change verification methods; those are controlled solely from the account’s security info.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.